bountyforge

Orchestrate eight parallel security agents to audit targets and compile reports.

332|46|Updated Apr 16, 2026
One-click install
npx skills add https://github.com/Gabson0x/bountyforge --skill bountyforge
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: bountyforge
Source: https://github.com/Gabson0x/bountyforge/tree/main
Command: npx skills add https://github.com/Gabson0x/bountyforge --skill bountyforge

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

Bug bounty programs require coordinating multiple security disciplines, collecting findings, and producing submission-ready reports. This Skill automates the orchestration of parallel audit agents and a canonical reporting workflow, reducing time to actionable results.

Core Features & Use Cases

  • Parallel agent orchestration: Spawns eight specialized security agents in parallel to audit web/API surfaces, smart contracts, and related infrastructure.
  • Gate-based evaluation & scoring: Applies the four-gate judging process and CVSS 3.1 scoring to validate findings and rank risk.
  • Platform-ready reporting: Formats outputs for HackerOne, Bugcrowd, Intigriti, Immunefi, and generic formats; supports deduplication, chain reasoning, and lead handling.
  • Local tooling integration: Integrates with local tooling and a Deepseek/Claude Code environment to execute code, collect evidence, and reproduce PoCs.
  • Reference-driven guidance: Uses references to standardized attack vectors and agent behavior to produce repeatable assessments.

Quick Start

Install this skill and run an audit against your target using the built-in workflow.

Frequently Asked Questions about bountyforge

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I orchestrate parallel bug bounty audits across web, API, and smart contract targets?

You can orchestrate parallel bug bounty audits by spawning eight specialized security agents in parallel to audit web/API surfaces, smart contracts, and infrastructure, compiling findings into platform-ready reports for submission.

How do I generate platform-ready bug bounty reports for HackerOne, Bugcrowd, and Immunefi?

To generate platform-ready bug bounty reports, the workflow formats audit outputs for HackerOne, Bugcrowd, Intigriti, Immunefi, and generic formats, supporting deduplication, chain reasoning, and lead handling to produce canonical reports.

Do I need a specific environment to execute parallel security audits and collect evidence?

Executing parallel security audits and collecting evidence requires local tooling and a Deepseek/Claude Code environment to execute code, reproduce PoCs, deduplicate findings, and generate canonical reports for submission.

How does CVSS scoring and gate-based evaluation work for security audit findings?

CVSS scoring and gate-based evaluation apply the four-gate judging process and CVSS 3.1 scoring to validate security audit findings and rank risk, ensuring only properly evaluated vulnerabilities proceed to reporting.

What is the best way to automate security audit orchestration and reduce time to actionable results?

The best way to automate security audit orchestration is using a reference-driven guidance system that automates spawning specialized agents, applying standardized attack vectors and agent behavior to produce repeatable assessments and reduce time to actionable results.

Are there limitations when using parallel security agents for bug bounty reporting?

Limitations of using parallel security agents include the requirement for specific local tooling and a Deepseek/Claude Code environment; without these dependencies, the system cannot execute code, collect evidence, or reproduce PoCs for bug bounty reporting.